SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84668

HIGH · CVSS 8.8 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Jenkins SAML Plugin versions 4.618.v441a_27fa_46d2 and earlier are vulnerable to an attack that enables the overwriting of the SAML identity provider metadata file via Stapler data binding. This flaw allows attackers to substitute the metadata with malicious content, potentially enabling them to authenticate as any user within the Jenkins environment. Organizations using this plugin should prioritize remediation to mitigate the risk of unauthorized access.

CVE
CVE-2026-84668
Severity
HIGH
CVSS
8.8
EPSS
0.26%
Jenkins

Original NVD Description

Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.